← Vulnerability feed

Vulnerability record · CVE-2022-24637 · published 18 March 2022

CVE-2022-24637: Open Web Analytics unauthenticated info leak leading to admin takeover

Openwebanalytics · Open Web Analytics

Open Web Analytics before 1.7.4 mishandles generated files that begin with '<?php' instead of the intended '<?php' sequence, so the PHP interpreter does not execute them. An unauthenticated remote attacker can read sensitive user information from these files and use cache hashes to escalate to administrator privileges. The flaw is critical because it is network-reachable with no authentication or user interaction and leads to full compromise of confidentiality, integrity and availability.

9.8 CVSS 3.1 Critical EPSS 99% · top 0.1% CWE-269 · Improper privilege management
9.8CVSS 3.1 base score, v2 5.0
99%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network exploitation with a 9.8 CVSS score, near-maximum EPSS and public exploit references makes this an urgent patch.

What it is

Open Web Analytics before 1.7.4 mishandles generated files that begin with '<?php' instead of the intended '<?php' sequence, so the PHP interpreter does not execute them. An unauthenticated remote attacker can read sensitive user information from these files and use cache hashes to escalate to administrator privileges. The flaw is critical because it is network-reachable with no authentication or user interaction and leads to full compromise of confidentiality, integrity and availability.

Impact

An attacker gains sensitive user data and, by leveraging cache hashes, can obtain administrative privileges over the OWA installation. That yields control of the analytics application and any data or integrations it manages.

Attack surface

Reachable over the network via HTTP against the OWA web application; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to trigger the information disclosure.

Exploitation

Not listed in CISA KEV, but EPSS is 0.99055 (99.9th percentile) and multiple references are tagged Exploit, including public remote code execution write-ups for 1.7.3. Treat exploitation as likely and publicly demonstrated.

What to do

  • Upgrade Open Web Analytics to 1.7.4 or later, which is the vendor release that addresses this issue.
  • If immediate upgrade is not possible, restrict network access to the OWA instance to trusted management networks only.
  • Review and rotate OWA administrator credentials and any secrets exposed through cached or generated files.
  • Monitor the vendor advisory and release notes for any further guidance tied to 1.7.4.

Detection

  • Inspect web server and OWA logs for unauthenticated requests to generated or cache file paths that return PHP source rather than executing.
  • Search the OWA installation for files beginning with the malformed '<?php' sequence that are served as static content.
  • Alert on anomalous administrative logins or privilege changes in OWA following suspicious unauthenticated requests.
  • Hunt for outbound or follow-on activity consistent with the public 1.7.3 remote code execution exploit chains.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24637 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-2294Openwebanalytics open web analytics injection vulnerabilityOpen Web Analytics (OWA) before 1.5.7 allows remote attackers to conduct PHP object injection attacks via a crafted serialized object in the owa_even…EPSS 2.7%8.8CVE-2014-1457Openwebanalytics open web analytics cross-site request forgery vulnerabilityOpen Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protectio…EPSS 1.1%7.5CVE-2014-1206Openwebanalytics open web analytics sql injection vulnerabilitySQL injection vulnerability in the password reset page in Open Web Analytics (OWA) before 1.5.5 allows remote attackers to execute arbitrary SQL comm…EPSS 2.5%5.1CVE-2010-2677Openwebanalytics open web analytics code injection vulnerabilityPHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is disabled and register_globals is…EPSS 2.7%5.0CVE-2010-2676Openwebanalytics open web analytics path traversal vulnerabilityMultiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers to read arbitrary files via …EPSS 2.9%4.3CVE-2014-1456Openwebanalytics open web analytics cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the login page in Open Web Analytics (OWA) before 1.5.6 allows remote attackers to inject arbitrary web s…EPSS 1.8%9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed

Source: NIST National Vulnerability Database (record CVE-2022-24637), CISA KEV, FIRST EPSS (scores of 2026-09-18). This page is refreshed as NVD updates the record.